Method of site isolation protection, electronic device and system using the same method
Abstract
A method of site isolation protection includes the following steps. A set of clustered engines including a first engine at a first site and a second engine at a second site is provided. A Fiber Channel (FC) connection and an Ethernet connection between the first and the second sites are provided. Whether an Ethernet Heartbeat (EH) from one of the first engine and the second engine through the Ethernet connection exists is detected when the FC connection fails. One of the first engine and the second engine is shut down when the EH exists. Furthermore, a quorum service at a client site is provided in different IP domain to further protect site isolation from happening, while the FC connection and Ethernet Heartbeat connection failed at the same time.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method of site isolation protection, comprising steps of:
providing a set of clustered engines including a first engine at a first site and a second engine at a second site;
providing a Fiber Channel (FC) connection and an Ethernet connection between the first and the second sites;
providing a quorum service;
detecting whether an Ethernet Heartbeat (EH) from one of the first engine and the second engine through the Ethernet connection exists when the FC connection fails;
shutting down one of the first engine and the second engine when the EH exists;
shutting down any engine which cannot access the quorum service; and
shutting down the second engine when the first engine is able to access the quorum service and the second engine can reach any engine at the first site, and otherwise keeping the second engine running.
2. A method as claimed in claim 1 , further comprising steps of:
setting corresponding internet protocol (IP) addresses respectively for the set of clustered engines; and
installing a quorum service at a client site, wherein the client site is in an IP domain being different from any one of those of the FC connection and the Ethernet connection.
3. A method as claimed in claim 1 , further comprising steps of:
shutting down the first engine when the first engine cannot access any of the storages at the first site, and shutting down the second engine when the second engine cannot access any of the storages at the second site; and
causing a local site engine in the set of clustered engines to continue to operate normally when the local site engine can access a remote site engine in the set of clustered engines through the FC connection.
4. A method as claimed in claim 1 , wherein:
a quorum service is installed at a client site and monitors the FC connection and the EH.
5. A method as claimed in claim 1 , further comprising steps of:
establishing site management tables to enable a site isolation service (SIS) through a telnet, wherein the site management table is configured to identify a primary engine and a secondary engine; and
keeping the primary engine operating while shutting down the secondary engine when the FC connection fails and the EH exists, wherein the first engine is the primary engine and the second engine is the secondary engine.
6. A method as claimed in claim 5 , further comprising:
maintaining a handshake for the EHs from all engines located at the other site when the SIS is enabled; and
providing information required for an FC isolation protection process.
7. A method as claimed in claim 6 , further comprising steps of:
enabling the SIS;
re-synchronizing the first engine and the second engine in the set of clustered engines when an FC fabric of the FC connection changes; and
re-evaluating the FC isolation protection process.
8. A method as claimed in claim 1 , comprising steps of:
detecting whether the FC connection fails and the EH does not exist;
keeping the first engine running when the first engine is able to access the quorum service, the FC connection fails and the EH does not exist; and
determining whether to shut down the second engine when the second engine is able to access the quorum service.
9. A method as claimed in claim 8 , wherein:
each engine in the set of clustered engines includes a first port for detecting the EHI and a second port for performing the quorum service;
the first engine and the second engine shut themselves down when the first engine and the second engine cannot access the quorum service; and
a failed communication between the first engine and the second engine causes a total isolation when neither of the first and the second engines can access to the other, wherein the total isolation is a condition when the FC connection fails and the Eli does not exist.
10. A system having site isolation protection, comprising:
a set of engines including a first engine at a first site and a second engine at a second site, and deployed at at-least-two sites;
a first transmission connection between the at least two sites;
a second transmission connection transmitting at least one transmission heartbeat (TH) between the at least two sites; and
a quorum service detecting at least one of a first state of the first transmission connection and a second state of an existence of the at least one TH, and issuing a specific command to the set of engines when the quorum service determines that at least one of the first state and the second state meets a specific criterion, including:
shutting down any engine which cannot access the quorum service; and
shutting down the second engine when the first engine is able to access the quorum service and the second engine can reach any engine at the first site, and otherwise keeping the second engine running.
11. A system as claimed in claim 10 , further comprising:
at least one first server at a first site;
at least two first storage devices containing first unique configuration information and first data information respectively;
at least two first switches are connected to the at least one first server and the at least two first storage devices, to form first multiple data paths from the at least one first server to the at least two first storage devices via each of the at least two first switches,
wherein the first engine is connected to the at least two first switches, configured to detect health conditions of the at least two first storage devices, and configured to control the at least two first switches to allow the at least one first server to access at least one of the at least two first storage devices through at least one of the first multiple data paths according to their respective health conditions;
at least one second server at a second site;
at least two second storage devices containing second unique configuration information and second data information respectively;
at least two second switches are connected to the at least one second server and the at least two second storage devices, to form second multiple data paths from the at least one second server to the at least two second storage devices via each of the at least two second switches,
wherein the second engine is connected to the at least two second switches, configured to detect health conditions of the at least two second storage devices, and configured to control the at least two second switches to allow the at least one second server to access at least one of the at least two second storage devices through at least one of the second multiple data paths according to their respective health conditions; wherein:
the FC connection connects the at least two first storage devices to the at least two second storage devices respectively;
each of the first engine and the second engine includes a first port detecting an Ethernet heartbeat of the Ethernet connection, and a second port performing the service; and
the Ethernet connection connects the first engine at the first site and the second engine at the second site.
12. A system as claimed in claim 10 , wherein:
the first transmission connection is a relatively high-speed transmission connection;
the second transmission connection is a relatively low-speed transmission connection;
the relatively high-speed transmission is a fiber channel (FC) connection;
the relatively low-speed transmission is an Ethernet connection;
each Transmission Heartbeat (TH) is an Ethernet heartbeat (EH);
the service is a quorum service;
a local site engine in the set of clustered engines continues to operate normally when the local site engine can access a remote site engine in the set of engines through the FC connection; and
the quorum service shuts down one of the first engine and the second engine when the quorum service detects that the first state of the FC connection is broken and the second state of the at least one EH exists.
13. A system as claimed in claim 10 , wherein:
the set of engines include a first engine at a first site and a second engine at a second site;
the quorum service shuts down the first engine when the first engine cannot access any of the storages at the first site, and shuts down the second engine when the second engine cannot access any of the storages at the second site; and
a local site engine in the set of clustered engines continues to operate normally when the local site engine can access a remote site engine in the set of engines through the FC connection.
14. A system as claimed in claim 10 , wherein:
the set of engines include a first engine at a first site and a second engine at a second site;
the quorum service keeps the first engine running when the first engine is able to access the service and both the FC connection and the Ethernet connection fail; and
the quorum service shuts down the second engine when the second engine can reach any engine at the first site, and otherwise the service keeps the second engine running.
15. A system as claimed in claim 10 , wherein:
the set of engines include a first engine at a first site and a second engine at a second site;
the quorum service establishes site management tables to enable a site isolation service (SIS) through a telnet, wherein the site management table is configured to identify a primary engine and a secondary engine;
the quorum service sets corresponding internet protocol (IP) addresses for the set of engines;
the quorum service keeps the primary engine operating and shuts down the secondary engine when the FC connection fails and the EH exists, wherein the first engine is the primary engine and the second engine is the secondary engine; and
the quorum service is installed at a client site, wherein the client site is in an IP domain being different from those of the FC connection and the Ethernet connection.
16. An electronic device in which a quorum service is installed, for use with site isolation protection, wherein two sites each has a set of engines, comprising:
a first module detecting at least one of a first state of a data connection between the two sites, and a second state of an existence of a link connection between the two sites; and
a second module issuing a specific command to the set of engines when the first module determines that at least one of the first state and the second state meets a specific criterion, wherein the set of engines includes a first engine at a first site and a second engine at a second site, and the specific criterion includes:
shutting down any engine which cannot access the quorum service; and
shutting down the second engine when the first engine is able to access the quorum service and the second engine can reach any engine at the first site, and otherwise keeping the second engine running.
17. An electronic device as claimed in claim 16 , wherein:
the data connection is a fiber channel (FC) connection, and the link connection is an Ethernet connection transmitting at least one Ethernet heartbeat (EH);
the first state occurs when the data connection fails or succeeds, and the second state occurs when the link connection fails or succeeds;
the first module detects whether an EH from one of the first and the second engines through the Ethernet connection exist when the FC connection fails;
the second module shuts down one of the first and the second engines when the EH from one of the first and the second engines exists;
the second module shuts down the first engine according to the specific command when the first engine cannot access any of the storages at the first site, and shuts down the second engine when the second engine cannot access any of the storages at the second site;
the second module causes a local site engine in the set of clustered engines to continue to operate normally when the local site engine can access a remote site engine in the set of engines through the FC connection; and
a quorum service is installed at a client site and monitors the FC connection and the EH.
18. An electronic device as claimed in claim 16 , wherein:
the data connection is a fiber channel (FC) connection, and the link connection is an Ethernet connection transmitting at least one Ethernet heartbeat (EH);
the electronic device determines corresponding internet protocol (IP) addresses respectively for the set of engines;
the electronic device is in an IP domain different from either one of those of the FC connection and the Ethernet connection;
the quorum service monitors the first state of the FC connection and the second state of the at least one EH in the set of the engines;
the electronic device establishes site management tables to enable a site isolation service (SIS) through a telnet, wherein the site management table is configured to identify a primary engine and a secondary engine;
the second module keeps the primary engine operating and shuts down the secondary engine when the FC connection fails and the at least one EH exists, wherein the set of engines include the first and the second engines, the first engine is the primary engine and the second engine is the secondary engine.
19. An electronic device as claimed in claim 16 , wherein:
the data connection is a fiber channel (FC) connection, and the link connection is an Ethernet connection transmitting at least one Ethernet heartbeat (EH);
the set of engines include a first engine at a first site and a second engine at a second site;
a quorum service is installed at the electronic device;
the first module detects whether the FC connection fails and the at least one EH does not exist;
the second module keeps the first engine running when the first engine is able to access the quorum service, the FC connection fails and the at least one EH does not exist;
the second module determines whether to shut down the second engine when the second engine is able to access the quorum service;
the second module shuts down any engine which cannot access the quorum service;
the second module shuts down the second engine when the second engine can reach any engine at the first site, and otherwise keeps the second engine running;
each engine in the set of engines includes a first port detecting the (EH) of the Ethernet connection and a second port performing the quorum service;
the first engine and the second engine shut themselves down when the first engine and the second engine cannot access the quorum service; and
a failed communication between the first engine and the second engine causes a total isolation when neither of the first engine and the second engine can access to the other, wherein the total isolation is a condition that the FC connection fails and the EH does not exist.Join the waitlist — get patent alerts
Track US10275325B2 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.